aceArt · WordPress Agency

WordPress Maintenance & Security

A WordPress website is never "finished". It has to be continuously maintained and hardened against new security vulnerabilities. We take over the maintenance of your WordPress site completely, from automated updates through backups to rapid intervention if things do catch fire.

Get expert advice

Ongoing maintenance: updates, backups, monitoring

WordPress itself, your theme and every installed plugin receive regular updates, including security-relevant ones. If these are skipped, open vulnerabilities pile up over months, which is exactly what makes WordPress a popular target. We apply updates in a controlled way, test them beforehand on a staging environment and keep a continuous eye on your site, including automated, regular backups so a clean restore point is ready in an emergency.

For us, maintenance also includes monitoring. We watch your site's availability, load times and unusual behaviour, so problems get noticed before they reach your visitors. For load times we use our own free tool SiteSentry, which monitors PageSpeed automatically and raises the alarm when a plugin update has made the site slower. All of this runs as a classic WordPress maintenance contract, with a guaranteed scope instead of vague aspiration.

Security plugins in use

Alongside our own processes, where it makes sense we rely on proven security plugins like Wordfence or Sucuri. They continuously monitor your installation for suspicious file changes, block automated attack attempts and raise the alarm as soon as something doesn't belong in your WordPress directory.

A security plugin is no substitute for real maintenance, though. It's an additional building block, not a replacement for current versions, clean user permissions and a watchful eye on your website.

Security: prevent instead of repair

Most successful attacks on WordPress sites exploit known, long-since-patched vulnerabilities in outdated plugins or themes. The most effective protection is therefore not being attackable in the first place: current versions, a lean plugin selection, restrictive user permissions and a login area that doesn't lie open to automated brute-force attempts.

What belongs to our security concept

  • Web application firewall and protection against automated brute-force login attempts
  • Regular security scans for malicious code and manipulated files
  • Encrypted connections (SSL/TLS) and cleanly configured HTTP security headers
  • Restrictive file and user permissions instead of WordPress default settings
  • Separate, encrypted backups outside the actual hosting environment

WordPress hacked or site down? Immediate help

If your site is already compromised (redirects to foreign domains, a Google warning, unknown admin accounts or simply a bad feeling), one thing counts above all: fast and considered action instead of panic. If necessary we take the site offline immediately, preserve the current state for analysis, identify the entry point and remove malicious code without residue, instead of merely papering over symptoms.

What you can do in the first few minutes

  • Change the passwords, for the WordPress admin, hosting, FTP and the database. A new password alone does not close the hole, but it cuts off ongoing access.
  • Overwrite nothing: do not restore a backup before the current state is preserved, otherwise the traces are gone and the cause stays open.
  • Delete nothing: please leave suspicious files and user accounts where they are, they are part of the analysis.
  • Tell your hosting provider, in case a suspension or an abuse notice has already come from there.
  • Note down what you spotted and when. The timing narrows things down considerably.

We take on the clean-up even if we have not looked after your site before. An existing contract is not a requirement.

After that we close the exploited gap, renew compromised credentials and accompany you through recovery if your site has been flagged as unsafe by Google. Then we set up ongoing maintenance and monitoring, so it never gets that far next time.

How a hack usually shows itself first

  • Unexpected redirects to foreign domains or spam content on your site
  • New, unknown users in the WordPress backend
  • Unusually high server load without a discernible reason
  • A Google warning that your website might be unsafe

For the clean-up we often take a radical but reliable route: the WordPress core folders wp-admin and wp-includes are completely replaced with fresh, official files, since they contain no custom content anyway. Particular attention goes to the uploads folder: it's writable and thus a popular entry point; executable files have absolutely no business being there.

Not every outage is a hack

When a site suddenly stays white or stops loading at all, the first thought is often an attack. Usually something more harmless is behind it, an update that went wrong or a memory limit at its ceiling. Knowing the symptom helps with the diagnosis. We look at both, the suspected attack and the technical fault.

Common failure patterns and what is usually behind them

  • White page with no error message: almost always a PHP error after an update, often a memory limit set too low or a plugin conflict.
  • Error establishing a database connection: the database is overloaded or offline, less often the credentials in wp-config.php have changed. That last one would be a warning sign.
  • Subpages return 404 while the homepage works: usually lost permalink rules, for instance after a move or a server change.
  • Changes do not show up: as a rule a caching problem at server, plugin or browser level.
  • Uploads fail: file permissions, disk space or an upload limit on the server that is set too small.

Some of this you can fix yourself with a bit of technical understanding. Once you start wondering whether a file has been tampered with, you have reached the point where it is better to call someone in than to keep trying things.

Frequently asked questions in an emergency

My WordPress site has been hacked, what do I do first?
Change the passwords for admin, hosting, FTP and the database, and do not overwrite the current state. Do not restore a backup before the status quo is preserved, and leave suspicious files or user accounts alone. Then get in touch with us and we take over the backup, the analysis and the clean-up.
Can you help if I am not a client?
Yes. We clean up compromised WordPress installations without an existing contract as well. What makes sense afterwards is a look at hosting, update status and the backup situation, because a hack is rarely the actual mistake, more often the consequence of one.
Should I just restore a backup?
Usually not as the first step. A backup rolls the site back to an older state but does not close the hole the attack came through. Without analysis the cleaned site is often affected again within days. So we preserve the status quo first, look for the entry point and decide afterwards whether a backup is the fastest route.
Google is warning about my site, how do I get out of that?
First the site has to be genuinely clean, after that a review can be requested in the Google Search Console. How fast the warning disappears is up to Google, not us. We handle the clean-up and the request and let you know as soon as the status changes.
How long does a clean-up take?
That depends on the extent. A single piece of injected malicious code is dealt with faster than an installation that has been infected unnoticed for months with several backdoors. After a first look we tell you what to expect, instead of naming a figure up front that will not hold.
My site is white or unreachable, is that a hack?
Not necessarily. More common are a PHP error after an update, a memory limit at its ceiling or an overloaded database. We narrow it down and tell you honestly whether it is a technical fault or a security incident.

Related topics

WordPress hosting

Reliable hosting is the basis of every security strategy. More on our WordPress hosting.

WordPress training

Admin training for your team ensures basic security rules are actually followed day to day. More on our WordPress training.

WordPress SEO

A Google security warning also affects your visibility in search. More on WordPress SEO.

Plugins in the multisite network

Every plugin lying unused in the network is attack surface and update effort. How to keep the overview in a multisite.

Ready for your WordPress project?

Tell us about your project. We'll get back to you promptly with an honest assessment.

Contact us
HOMEWORDPRESS-MAINTENANCE-SECURITY